- It follows a per-process capability-based model
- It compartmentalises the system, according to access capabilities, to APIs and files
- It makes sure that the users can make policy decisions they understand
- It is Kernel mediated but server enforced
- It is a fine-grained way to efficiently restrict or completely prevent unauthorised access to sensitive APIs and data on the mobile phone while keeping the device open to developers.
No comments:
Post a Comment